PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66692 Colissimo CVE debrief

The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin, version 2.10.0 and below, contains a Customer Insecure Direct Object References (IDOR) vulnerability. This vulnerability allows unauthorized access to sensitive data or functionality, potentially leading to information disclosure or other security issues. Defenders should verify their inventory and monitor for vendor remediation. The CVE record was published on 2026-08-06T15:17:22.357Z and has not been modified since then.

Vendor
Colissimo
Product
Colissimo Officiel : Méthodes de livraison pour WooCommerce
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-08
Advisory published
2026-08-06
Advisory updated
2026-08-08

Who should care

Defenders of WooCommerce installations using Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin should verify their inventory and monitor for vendor remediation. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess the potential impact and take necessary actions to protect their systems.

Technical summary

The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin, version 2.10.0 and below, has a Customer Insecure Direct Object References (IDOR) vulnerability. This vulnerability allows unauthorized access to sensitive data or functionality, potentially leading to information disclosure or other security issues. The vulnerability is classified as a medium severity issue, with a CVSS score of 4.3.

Defensive priority

Defenders should prioritize verification of affected scope and vendor remediation status.

Recommended defensive actions

  • Verify affected scope and inventory
  • Monitor for vendor remediation
  • Implement compensating controls
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

Evidence is limited; primary official records indicate a Customer Insecure Direct Object References (IDOR) vulnerability in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions. Defenders should verify their inventory and monitor for vendor remediation. The source details are limited, and further verification is required to confirm the affected scope and severity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:22.357Z and has not been modified since then.